RUSTSEC-2026-0128
Double-free and use-after-free in `Keys::next()`
Details
`Keys::next()` uses `ptr::read` to move out the `Option<V>` by value, which drops the contained `V` when `V` is non-Copy (e.g. `String`). This leaves a dangling value in the map's storage slot. Subsequent `get()` operations on that key return a dangling reference to already-freed memory.
This can be triggered through safe public APIs — `Map::keys()`, `Keys::next()`, and `Map::get()` — with no `unsafe` required from the caller. Under Miri, accessing the freed slot produces "Undefined Behavior: pointer not dereferenceable: alloc has been freed, so this pointer is dangling".
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0No fixed version published yet for emap. Pin to a known-safe version or switch to an alternative.